The indexed-btree npm package can trigger malware during normal application activity

The indexed-btree npm package can trigger malware during normal application activity. Projects using the indexed-btree N P M package may have executed malware during ordinary application activity.

Daily Cyber News: The indexed-btree npm package can trigger malware during normal application activity

Projects using the indexed-btree N P M package may have executed malware during ordinary application activity. The package copied the identity of the legitimate sorted-btree library and recorded almost two million weekly downloads. However, it didn’t use a preinstall or postinstall script.

Key context: Once triggered, the code profiled the host, contacted attacker-controlled infrastructure, and retrieved a second-stage payload using information stored in a blockchain contract.

Additional detail: Download totals don’t show how many systems actually ran the malicious path, so teams need to distinguish between packages that were installed and packages used in a running process.

For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

Topics: cybersecurity news, cybersecurity, cyber risk, malware, indexed-btree, package, trigger, during, normal, application.

The indexed-btree npm package can trigger malware during normal application activity
Broadcast by